#bushehr — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bushehr, aggregated by home.social.
-
https://www.europesays.com/ee/230054/ USA ründas taas Iraani, kelle väitel sai pihta ka tsiviiltaristu #Bahrein #BandarAbbas #BreakingNews #BreakingNews #Bushehr #CENTCOM #DonaldTrump #EE #Eesti #EestiKeel #Estonia #Estonian #FeaturedNews #FeaturedNews #Headlines #Iraan #KarolineLeavitt #Kuveit #LatestNews #LatestNews #News #OmaaniLaht #PopulaarseimadLood #Teheran #TopStories #TopStories #ÜldisedUudised #usa #Uudised #ValgeMaja(USA) #ViimasedUudised
-
https://www.europesays.com/iran/210264/ US and Iran exchange blows in rekindled Middle East war #ahvaz #BandarAbbas #Bushehr #DonaldTrump #EsmaeilBaqaei #FatemehMohajerani #GulfOfOman #Iran #IRNA #Jordan #KarolineLeavitt #Kuwait #MiddleEast #MohammadBagherGhalibaf #Pakistan #StraitOfHormuz #TahirAndrabi #Tehran #UnitedStates
-
US and Iran exchange blows in rekindled Middle East war
The United States struck Iran and Tehran attacked US allies in the Gulf on Thursday as the foes…
#NewsBeep #News #BreakingNews #Ahvaz #BandarAbbas #breakingnews #Bushehr #DonaldTrump #EsmaeilBaqaei #FatemehMohajerani #GulfofOman #Iran #IRNA #Jordan #KarolineLeavitt #Kuwait #MiddleEast #MohammadBagherGhalibaf #Pakistan #StraitofHormuz #TahirAndrabi #Tehran #UnitedStates
https://www.newsbeep.com/647209/ -
US and Iran exchange blows in rekindled Middle East war
The United States struck Iran and Tehran attacked US allies in the Gulf on Thursday as the foes…
#Conflict #Conflicts #War #ahvaz #BandarAbbas #Bushehr #DonaldTrump #EsmaeilBaqaei #FatemehMohajerani #GulfofOman #Iran #IRNA #jordan #KarolineLeavitt #kuwait #middleeast #MohammadBagherGhalibaf #pakistan #StraitofHormuz #tahirandrabi #Tehran #UnitedStates
https://www.europesays.com/3135178/ -
Estados Unidos lanza nueva ofensiva militar contra Irán
EE.UU. completa una nueva oleada de ataques contra objetivos militares de Irán.
SN Redacción | EFE
Washington.- El Comando Central de Estados Unidos (Centcom) informó este lunes que descubrió una nueva oleada de ataques contra objetivos militares en Irán, en una operación de cinco horas que concluyó a las 22:15 hora del este (02:15 GMT del martes).
Según el mando militar, las fuerzas estadounidenses atacaron objetivos en Bushehr, Chah Bahar, Jask, Konarak, Abu Musa y Bandar Abbas, empleando municiones de precisión contra sistemas de defensa costera, instalaciones de misiles y drones, así como capacidades marítimas iraníes, con el objetivo de seguir reduciendo la capacidad de Teherán para atacar el transporte marítimo comercial.
El Centcom agregó que más de 50.000 militares estadounidenses permanecen desplegados en el Oriente Medio y aseguró que las fuerzas de Estados Unidos continúan «vigilantes, letales y preparadas» para responder a cualquier amenaza en la región.
Con fuerza a Irán «esta noche» y «mañana»
Previamente, Trump durante una entrevista en el programa del comentarista conservador Hugh Hewitt indicó que esta noche y mañana golpearían «muy duro» a Irán.
Aunque el republicano había evitado inicialmente hablar de posibles objetivos militares de la nueva ola de ataques, al ser cuestionado por el entrevistador dejó ver que existía una posibilidad de atacar una zona céntrica de Irán donde se presume que podría existir una cuarta instalación nuclear.
«Vamos a golpearlos muy duro esta noche y vamos a golpearlos muy duro mañana, y no hay absolutamente nada que pueda hacer al respecto», declaró Trump durante una entrevista con el comentarista político conservador Hewitt, y aseguró que hay posibles objetivos militares identificados.
Durante la entrevista, Trump afirmó que entre los posibles objetivos se encontraba el monte Kolang Gaz La, ubicado en la provincia de Isfahán, en el centro de Irán, donde presuntamente la República Islámica tendría una cuarta instalación nuclear.
«Es un objetivo posible para un buen y certero disparo directo a la puerta principal», respondió Trump sobre la posibilidad de atacar esta zona.
Trump reactiva el bloqueo marítimo en Irán
Horas antes, el mandatario dijo que Washington reanudará el bloqueo del tráfico marítimo que entra y venta de los puertos iraníes, y que entrará en vigor mañana martes 14 de julio a las 16.00 hora del este (20:00 GMT).
Asimismo, anunció el cobro de un 20 % como compensación por la protección a embarcaciones de otros países que transiten por el estrecho de Ormuz, tras restablecer el bloqueo naval contra Irán.
Estos llegan después de que Estados Unidos e Irán hayan intercambiado ataques desde la semana pasada en el golfo Pérsico, lo que supuso la ruptura del alto medidas el fuego acordado en el memorándum de entendimiento firmado el 17 de junio.
Trump: Irán buscó seguir negociando pese a un acuerdo alcanzado
Trump también afirmó este lunes que Irán quería continuar las negociaciones pese a que, según dijo, ambos países habían alcanzado un «acuerdo» dos días antes, en medio de las tensiones entre Washington y Teherán.
«Creo que tuvimos un acuerdo con ellos hace dos días, pero ellos querían seguir negociando», aseguró Trump ante periodistas en el Despacho Oval, sin ofrecer detalles sobre el supuesto pacto ni sobre las condiciones del mismo.
Trump aseguró que, pese a las conversaciones con Teherán, su Gobierno no llegó a cerrar un acuerdo definitivo porque Irán habría optado por prolongar el diálogo.
El mandatario no explicó qué puntos incluían el supuesto entendimiento alcanzado «hace dos días» ni quiénes participarían en esas negociaciones.
El presidente estadounidense insistió en que la presión sobre Irán continuará mientras no exista un pacto que satisfaga a Washington y defendió el uso combinado de medidas económicas y militares como mecanismo para forzar a Teherán a aceptar sus condiciones.
Trump afirmó que su objetivo sigue siendo evitar que Irán o desarrollar capacidades que consideren una amenaza para Estados Unidos y sus aliados. –sn–
Sociedad Noticias¡Conéctate con Sociedad Noticias! Suscríbete a nuestro canal de YouTube y activa las notificaciones, o bien, síguenos en las redes sociales: Facebook, Twitter e Instagram.
También, te invitamos a que te sumes a nuestro canal de información en tiempo real a través de Telegram.
#NoticiasMX #PeriodismoParaTi #PeriodismoParaTiSociedadNoticias #AbuMusa #ataqueMilitar #BandarAbbas #Bushehr #Cdmx #CENTCOM #ChahBahar #ComandoCentralDeEstadosUnidos #conflictoIránEstadosUnidos #defensaCostera #DonaldTrump #drones #EstadosUnidos #geopolítica #golfoPérsico #Información #InformaciónMéxico #irán #Jask #Konarak #México #misiles #Morena #noticia #noticias #NoticiasMéxico #NoticiasSociedad #OrienteMedio #seguridadInternacional #SN #Sociedad #SociedadNoticias #SociedadNoticiasCom #sociedadNoticias #SociedadNoticiasCom #tensiónInternacional #transporteMarítimo -
⭕Des frappes aériennes #Américaines intenses ciblent des sites militaires dans les provinces #Iraniennes de #Bushehr et #d'Hormozgan.
#Eye-On-Palestine
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mqkunvsx652a -
⭕Des frappes aériennes #Américaines intenses ciblent des sites militaires dans les provinces #Iraniennes de #Bushehr et #d'Hormozgan.
#Eye-On-Palestine
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mqkunvsx652a -
⭕Des frappes aériennes #Américaines intenses ciblent des sites militaires dans les provinces #Iraniennes de #Bushehr et #d'Hormozgan.
#Eye-On-Palestine
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mqkunvsx652a -
⭕Les frappes #Américaines sur #l’Iran sont très intenses ce soir.
Les villes de #Kish, #Bushehr, #Jask, #Bandar-Kangan et #Kanarak sont touchées.
#InfoSudLiban
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mqksdjkfmf2a -
⭕Les frappes #Américaines sur #l’Iran sont très intenses ce soir.
Les villes de #Kish, #Bushehr, #Jask, #Bandar-Kangan et #Kanarak sont touchées.
#InfoSudLiban
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mqksdjkfmf2a -
⭕Les frappes #Américaines sur #l’Iran sont très intenses ce soir.
Les villes de #Kish, #Bushehr, #Jask, #Bandar-Kangan et #Kanarak sont touchées.
#InfoSudLiban
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mqksdjkfmf2a -
⭕️ Des frappes #Américaines ont visé #l’Iran ce soir, #Bandar #Abbas, #Sirik, l’île de #Lavand et #Abu-Moussa, #Chabahar, #Bushehr, #Konarak et #Jask touchées.
Les frappes sont encore en cours.
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mq62ltwwxd2y -
⭕️ Des frappes #Américaines ont visé #l’Iran ce soir, #Bandar #Abbas, #Sirik, l’île de #Lavand et #Abu-Moussa, #Chabahar, #Bushehr, #Konarak et #Jask touchées.
Les frappes sont encore en cours.
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mq62ltwwxd2y -
⭕️ Des frappes #Américaines ont visé #l’Iran ce soir, #Bandar #Abbas, #Sirik, l’île de #Lavand et #Abu-Moussa, #Chabahar, #Bushehr, #Konarak et #Jask touchées.
Les frappes sont encore en cours.
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mq62ltwwxd2y -
⭕️ Des frappes #Américaines ont visé #l’Iran ce soir, #Bandar #Abbas, #Sirik, l’île de #Lavand et #Abu-Moussa, #Chabahar, #Bushehr, #Konarak et #Jask touchées.
Les frappes sont encore en cours.
RE: https://bsky.app/profile/did:plc:2cte4wipyk47qjujtxrskqcx/post/3mq62ltwwxd2y -
4 April "🇮🇷 #Iran War: Renewed attack on #Bushehr #Nuclear Power Plant Security personnel killed Nuclear power plant ancillary building damaged Nuclear lobby: #Nuclear power plants must not be attacked" '🇷🇺 #Rosatom evacuates its employees .. developments near the NPP represent worst-case scenario'
RE: https://bsky.app/profile/did:plc:yd4huluhnrewiaa6eatgisaf/post/3mip6kfkqi22s -
Escalada crítica en Irán: ataque a planta nuclear de Bushehr y complejo petroquímico deja seis muertos | vía #UChileRadio
#ataquenuclear #bushehr #crisisenergética #irán #rafaelgrossi #rosatom
-
'Remember Western outrage about hostilities near Zaporozhye nuclear power plant?'
Iran's FM Araghchi on latest Bushehr plant attack: 'radioactive fallout will END LIFE in GCC capitals, NOT Tehran'
#Bushehr #NuclearDisaster #PersianGulf #WarOfAggression
#RegimeChange #WarOnIran #EpsteinWar #WestAsia #Iran #tRump #WarForOil #Israel -
'Remember Western outrage about hostilities near Zaporozhye nuclear power plant?'
Iran's FM Araghchi on latest Bushehr plant attack: 'radioactive fallout will END LIFE in GCC capitals, NOT Tehran'
#Bushehr #NuclearDisaster #PersianGulf #WarOfAggression
#RegimeChange #WarOnIran #EpsteinWar #WestAsia #Iran #tRump #WarForOil #Israel -
Of course, now we know who was behind #Stuxnet -- #Israel and the #CIA -- thanks!
Why the #StuxnetWorm is like nothing seen before
By Paul Marks
27 September 2010"Stuxnet is the first worm of its type capable of attacking #CriticalInfrastructure like #PowerStations and #ElectricityGrids: those in the know have been expecting it for years. On 26 September, #Iran’s state news agency reported that computers at its #Bushehr #NuclearPowerPlant had been infected.
Why the fuss over Stuxnet?
"#ComputerViruses, worms and #trojans have until now mainly infected PCs or the servers that keep e-businesses running. They may delete key system files or documents, or perhaps prevent website access, but they do not threaten life and limb.
"The Stuxnet worm is different. It is the first piece of #malware so far able to break into the types of computer that control machinery at the heart of industry, allowing an attacker to assume control of critical systems like #pumps, #motors, #alarms and #valves in an industrial plant.
"In the worst case scenarios, safety systems could be switched off at a nuclear power plant; fresh water #contaminated with effluent at a #SewageTreatmentPlant, or the valves in an #OilPipeline opened, contaminating the land or sea.
“'Giving an attacker control of industrial systems like a #dam, a sewage plant or a power station is extremely unusual and makes this a serious threat with huge real world implications,' says Patrick Fitzgerald, senior threat intelligence officer with Symantec. 'It has changed everything.'
Why is a different type of worm needed to attack an industrial plant?
"Industrial machinery is not controlled directly by the kind of computers we all use. Instead, the equipment used in an industrial process is controlled by a separate, dedicated system called a programmable logic controller (#PLC) which runs supervisory control and data acquisition software (#SCADA).
"Running the SCADA software, the PLC controls the process at hand within strict safety limits, switching motors on and off, say, and emptying vessels, and feeding back data which may safely modify the process without the need for human intervention – the whole point of industrial automation.
So how does a worm get into the system?
"It is not easy because they do not run regular PC, Mac or Linux software. Instead, the firms who sell PLCs each have their own programming language – and that has made it tricky for hackers to break it.
"However there is a way in via the Windows PC that oversees the PLC’s operations. Stuxnet exploited four vulnerabilities in Microsoft Windows to give a remote hacker the ability to inject malicious code into a market-leading PLC made by German electronics conglomerate Siemens.
"That’s possible because PLCs are not well-defended devices. They operate for many years in situ and electronic access to them is granted via well-known passwords that are rarely changed. Even when Stuxnet was identified, Siemens opposed password changes on the grounds that it could cause chaos as older systems tried to communicate using old passwords.
Where did the initial Stuxnet infection come from?
"It appears to have first arrived in Iran on a simple #USBMemoryStick, says Fitzgerald. His team in Dublin, Ireland has been analysing Stuxnet since it was first identified by a security team in Belarus in June.
"The first of the four Windows vulnerabilities allowed executable code on a USB stick to spread to a PC. The USB may have been given to an Iranian plant operative – or simply left somewhere for an inquisitive person to insert into their terminal.
"Says Fitzgerald: 'It then spreads from machine to machine on the network, exploiting a second vulnerability to do so, and reports back to the attacker on the internet when it finds a PC that’s running Siemens SCADA software. The attacker can then download a diagram of the industrial system set-up the SCADA controls.'
"The next two Windows vulnerabilities lets the worm escalate its privilege levels to allow the attacker to inject Siemens PLC format computer code – written in a language called STL – into the PLC. It’s that code which is capable of performing the skulduggery: perhaps turning off alarms, or resetting safe temperature levels.
How do we know where Stuxnet is active?
"Symantec monitored communications with the two internet domains that the worm swaps data with. By geotagging the IP addresses of Stuxnet-infected computers in communication with the attacker, Fitzgerald’s team found that 58.8 per cent of infections were in Iran, 18.2 per cent in #Indonesia, 8.3 per cent in #India, 2.6 per cent in #Azerbaijan and 1.6 per cent in the US.
Who is behind the worm?
"No one knows. It is however very professionally written, requiring what Fitzgerald calls 'a broad spectrum of skills' to exploit four new vulnerabilities and develop their own SCADA/PLC set-up to test it on.
"This has some commentators suggesting that a #NationState with plenty of technical resources may have been behind Stuxnet. But computer crime is a billion dollar business so such an effort is not beyond extortionists.
"Stuxnet comprises a 600-kilobyte file and it has not yet been fully analysed."
Read more:
https://www.newscientist.com/article/dn19504-why-the-stuxnet-worm-is-like-nothing-seen-before/ -
Of course, now we know who was behind #Stuxnet -- #Israel and the #CIA -- thanks!
Why the #StuxnetWorm is like nothing seen before
By Paul Marks
27 September 2010"Stuxnet is the first worm of its type capable of attacking #CriticalInfrastructure like #PowerStations and #ElectricityGrids: those in the know have been expecting it for years. On 26 September, #Iran’s state news agency reported that computers at its #Bushehr #NuclearPowerPlant had been infected.
Why the fuss over Stuxnet?
"#ComputerViruses, worms and #trojans have until now mainly infected PCs or the servers that keep e-businesses running. They may delete key system files or documents, or perhaps prevent website access, but they do not threaten life and limb.
"The Stuxnet worm is different. It is the first piece of #malware so far able to break into the types of computer that control machinery at the heart of industry, allowing an attacker to assume control of critical systems like #pumps, #motors, #alarms and #valves in an industrial plant.
"In the worst case scenarios, safety systems could be switched off at a nuclear power plant; fresh water #contaminated with effluent at a #SewageTreatmentPlant, or the valves in an #OilPipeline opened, contaminating the land or sea.
“'Giving an attacker control of industrial systems like a #dam, a sewage plant or a power station is extremely unusual and makes this a serious threat with huge real world implications,' says Patrick Fitzgerald, senior threat intelligence officer with Symantec. 'It has changed everything.'
Why is a different type of worm needed to attack an industrial plant?
"Industrial machinery is not controlled directly by the kind of computers we all use. Instead, the equipment used in an industrial process is controlled by a separate, dedicated system called a programmable logic controller (#PLC) which runs supervisory control and data acquisition software (#SCADA).
"Running the SCADA software, the PLC controls the process at hand within strict safety limits, switching motors on and off, say, and emptying vessels, and feeding back data which may safely modify the process without the need for human intervention – the whole point of industrial automation.
So how does a worm get into the system?
"It is not easy because they do not run regular PC, Mac or Linux software. Instead, the firms who sell PLCs each have their own programming language – and that has made it tricky for hackers to break it.
"However there is a way in via the Windows PC that oversees the PLC’s operations. Stuxnet exploited four vulnerabilities in Microsoft Windows to give a remote hacker the ability to inject malicious code into a market-leading PLC made by German electronics conglomerate Siemens.
"That’s possible because PLCs are not well-defended devices. They operate for many years in situ and electronic access to them is granted via well-known passwords that are rarely changed. Even when Stuxnet was identified, Siemens opposed password changes on the grounds that it could cause chaos as older systems tried to communicate using old passwords.
Where did the initial Stuxnet infection come from?
"It appears to have first arrived in Iran on a simple #USBMemoryStick, says Fitzgerald. His team in Dublin, Ireland has been analysing Stuxnet since it was first identified by a security team in Belarus in June.
"The first of the four Windows vulnerabilities allowed executable code on a USB stick to spread to a PC. The USB may have been given to an Iranian plant operative – or simply left somewhere for an inquisitive person to insert into their terminal.
"Says Fitzgerald: 'It then spreads from machine to machine on the network, exploiting a second vulnerability to do so, and reports back to the attacker on the internet when it finds a PC that’s running Siemens SCADA software. The attacker can then download a diagram of the industrial system set-up the SCADA controls.'
"The next two Windows vulnerabilities lets the worm escalate its privilege levels to allow the attacker to inject Siemens PLC format computer code – written in a language called STL – into the PLC. It’s that code which is capable of performing the skulduggery: perhaps turning off alarms, or resetting safe temperature levels.
How do we know where Stuxnet is active?
"Symantec monitored communications with the two internet domains that the worm swaps data with. By geotagging the IP addresses of Stuxnet-infected computers in communication with the attacker, Fitzgerald’s team found that 58.8 per cent of infections were in Iran, 18.2 per cent in #Indonesia, 8.3 per cent in #India, 2.6 per cent in #Azerbaijan and 1.6 per cent in the US.
Who is behind the worm?
"No one knows. It is however very professionally written, requiring what Fitzgerald calls 'a broad spectrum of skills' to exploit four new vulnerabilities and develop their own SCADA/PLC set-up to test it on.
"This has some commentators suggesting that a #NationState with plenty of technical resources may have been behind Stuxnet. But computer crime is a billion dollar business so such an effort is not beyond extortionists.
"Stuxnet comprises a 600-kilobyte file and it has not yet been fully analysed."
Read more:
https://www.newscientist.com/article/dn19504-why-the-stuxnet-worm-is-like-nothing-seen-before/ -
Of course, now we know who was behind #Stuxnet -- #Israel and the #CIA -- thanks!
Why the #StuxnetWorm is like nothing seen before
By Paul Marks
27 September 2010"Stuxnet is the first worm of its type capable of attacking #CriticalInfrastructure like #PowerStations and #ElectricityGrids: those in the know have been expecting it for years. On 26 September, #Iran’s state news agency reported that computers at its #Bushehr #NuclearPowerPlant had been infected.
Why the fuss over Stuxnet?
"#ComputerViruses, worms and #trojans have until now mainly infected PCs or the servers that keep e-businesses running. They may delete key system files or documents, or perhaps prevent website access, but they do not threaten life and limb.
"The Stuxnet worm is different. It is the first piece of #malware so far able to break into the types of computer that control machinery at the heart of industry, allowing an attacker to assume control of critical systems like #pumps, #motors, #alarms and #valves in an industrial plant.
"In the worst case scenarios, safety systems could be switched off at a nuclear power plant; fresh water #contaminated with effluent at a #SewageTreatmentPlant, or the valves in an #OilPipeline opened, contaminating the land or sea.
“'Giving an attacker control of industrial systems like a #dam, a sewage plant or a power station is extremely unusual and makes this a serious threat with huge real world implications,' says Patrick Fitzgerald, senior threat intelligence officer with Symantec. 'It has changed everything.'
Why is a different type of worm needed to attack an industrial plant?
"Industrial machinery is not controlled directly by the kind of computers we all use. Instead, the equipment used in an industrial process is controlled by a separate, dedicated system called a programmable logic controller (#PLC) which runs supervisory control and data acquisition software (#SCADA).
"Running the SCADA software, the PLC controls the process at hand within strict safety limits, switching motors on and off, say, and emptying vessels, and feeding back data which may safely modify the process without the need for human intervention – the whole point of industrial automation.
So how does a worm get into the system?
"It is not easy because they do not run regular PC, Mac or Linux software. Instead, the firms who sell PLCs each have their own programming language – and that has made it tricky for hackers to break it.
"However there is a way in via the Windows PC that oversees the PLC’s operations. Stuxnet exploited four vulnerabilities in Microsoft Windows to give a remote hacker the ability to inject malicious code into a market-leading PLC made by German electronics conglomerate Siemens.
"That’s possible because PLCs are not well-defended devices. They operate for many years in situ and electronic access to them is granted via well-known passwords that are rarely changed. Even when Stuxnet was identified, Siemens opposed password changes on the grounds that it could cause chaos as older systems tried to communicate using old passwords.
Where did the initial Stuxnet infection come from?
"It appears to have first arrived in Iran on a simple #USBMemoryStick, says Fitzgerald. His team in Dublin, Ireland has been analysing Stuxnet since it was first identified by a security team in Belarus in June.
"The first of the four Windows vulnerabilities allowed executable code on a USB stick to spread to a PC. The USB may have been given to an Iranian plant operative – or simply left somewhere for an inquisitive person to insert into their terminal.
"Says Fitzgerald: 'It then spreads from machine to machine on the network, exploiting a second vulnerability to do so, and reports back to the attacker on the internet when it finds a PC that’s running Siemens SCADA software. The attacker can then download a diagram of the industrial system set-up the SCADA controls.'
"The next two Windows vulnerabilities lets the worm escalate its privilege levels to allow the attacker to inject Siemens PLC format computer code – written in a language called STL – into the PLC. It’s that code which is capable of performing the skulduggery: perhaps turning off alarms, or resetting safe temperature levels.
How do we know where Stuxnet is active?
"Symantec monitored communications with the two internet domains that the worm swaps data with. By geotagging the IP addresses of Stuxnet-infected computers in communication with the attacker, Fitzgerald’s team found that 58.8 per cent of infections were in Iran, 18.2 per cent in #Indonesia, 8.3 per cent in #India, 2.6 per cent in #Azerbaijan and 1.6 per cent in the US.
Who is behind the worm?
"No one knows. It is however very professionally written, requiring what Fitzgerald calls 'a broad spectrum of skills' to exploit four new vulnerabilities and develop their own SCADA/PLC set-up to test it on.
"This has some commentators suggesting that a #NationState with plenty of technical resources may have been behind Stuxnet. But computer crime is a billion dollar business so such an effort is not beyond extortionists.
"Stuxnet comprises a 600-kilobyte file and it has not yet been fully analysed."
Read more:
https://www.newscientist.com/article/dn19504-why-the-stuxnet-worm-is-like-nothing-seen-before/ -
Of course, now we know who was behind #Stuxnet -- #Israel and the #CIA -- thanks!
Why the #StuxnetWorm is like nothing seen before
By Paul Marks
27 September 2010"Stuxnet is the first worm of its type capable of attacking #CriticalInfrastructure like #PowerStations and #ElectricityGrids: those in the know have been expecting it for years. On 26 September, #Iran’s state news agency reported that computers at its #Bushehr #NuclearPowerPlant had been infected.
Why the fuss over Stuxnet?
"#ComputerViruses, worms and #trojans have until now mainly infected PCs or the servers that keep e-businesses running. They may delete key system files or documents, or perhaps prevent website access, but they do not threaten life and limb.
"The Stuxnet worm is different. It is the first piece of #malware so far able to break into the types of computer that control machinery at the heart of industry, allowing an attacker to assume control of critical systems like #pumps, #motors, #alarms and #valves in an industrial plant.
"In the worst case scenarios, safety systems could be switched off at a nuclear power plant; fresh water #contaminated with effluent at a #SewageTreatmentPlant, or the valves in an #OilPipeline opened, contaminating the land or sea.
“'Giving an attacker control of industrial systems like a #dam, a sewage plant or a power station is extremely unusual and makes this a serious threat with huge real world implications,' says Patrick Fitzgerald, senior threat intelligence officer with Symantec. 'It has changed everything.'
Why is a different type of worm needed to attack an industrial plant?
"Industrial machinery is not controlled directly by the kind of computers we all use. Instead, the equipment used in an industrial process is controlled by a separate, dedicated system called a programmable logic controller (#PLC) which runs supervisory control and data acquisition software (#SCADA).
"Running the SCADA software, the PLC controls the process at hand within strict safety limits, switching motors on and off, say, and emptying vessels, and feeding back data which may safely modify the process without the need for human intervention – the whole point of industrial automation.
So how does a worm get into the system?
"It is not easy because they do not run regular PC, Mac or Linux software. Instead, the firms who sell PLCs each have their own programming language – and that has made it tricky for hackers to break it.
"However there is a way in via the Windows PC that oversees the PLC’s operations. Stuxnet exploited four vulnerabilities in Microsoft Windows to give a remote hacker the ability to inject malicious code into a market-leading PLC made by German electronics conglomerate Siemens.
"That’s possible because PLCs are not well-defended devices. They operate for many years in situ and electronic access to them is granted via well-known passwords that are rarely changed. Even when Stuxnet was identified, Siemens opposed password changes on the grounds that it could cause chaos as older systems tried to communicate using old passwords.
Where did the initial Stuxnet infection come from?
"It appears to have first arrived in Iran on a simple #USBMemoryStick, says Fitzgerald. His team in Dublin, Ireland has been analysing Stuxnet since it was first identified by a security team in Belarus in June.
"The first of the four Windows vulnerabilities allowed executable code on a USB stick to spread to a PC. The USB may have been given to an Iranian plant operative – or simply left somewhere for an inquisitive person to insert into their terminal.
"Says Fitzgerald: 'It then spreads from machine to machine on the network, exploiting a second vulnerability to do so, and reports back to the attacker on the internet when it finds a PC that’s running Siemens SCADA software. The attacker can then download a diagram of the industrial system set-up the SCADA controls.'
"The next two Windows vulnerabilities lets the worm escalate its privilege levels to allow the attacker to inject Siemens PLC format computer code – written in a language called STL – into the PLC. It’s that code which is capable of performing the skulduggery: perhaps turning off alarms, or resetting safe temperature levels.
How do we know where Stuxnet is active?
"Symantec monitored communications with the two internet domains that the worm swaps data with. By geotagging the IP addresses of Stuxnet-infected computers in communication with the attacker, Fitzgerald’s team found that 58.8 per cent of infections were in Iran, 18.2 per cent in #Indonesia, 8.3 per cent in #India, 2.6 per cent in #Azerbaijan and 1.6 per cent in the US.
Who is behind the worm?
"No one knows. It is however very professionally written, requiring what Fitzgerald calls 'a broad spectrum of skills' to exploit four new vulnerabilities and develop their own SCADA/PLC set-up to test it on.
"This has some commentators suggesting that a #NationState with plenty of technical resources may have been behind Stuxnet. But computer crime is a billion dollar business so such an effort is not beyond extortionists.
"Stuxnet comprises a 600-kilobyte file and it has not yet been fully analysed."
Read more:
https://www.newscientist.com/article/dn19504-why-the-stuxnet-worm-is-like-nothing-seen-before/ -
Of course, now we know who was behind #Stuxnet -- #Israel and the #CIA -- thanks!
Why the #StuxnetWorm is like nothing seen before
By Paul Marks
27 September 2010"Stuxnet is the first worm of its type capable of attacking #CriticalInfrastructure like #PowerStations and #ElectricityGrids: those in the know have been expecting it for years. On 26 September, #Iran’s state news agency reported that computers at its #Bushehr #NuclearPowerPlant had been infected.
Why the fuss over Stuxnet?
"#ComputerViruses, worms and #trojans have until now mainly infected PCs or the servers that keep e-businesses running. They may delete key system files or documents, or perhaps prevent website access, but they do not threaten life and limb.
"The Stuxnet worm is different. It is the first piece of #malware so far able to break into the types of computer that control machinery at the heart of industry, allowing an attacker to assume control of critical systems like #pumps, #motors, #alarms and #valves in an industrial plant.
"In the worst case scenarios, safety systems could be switched off at a nuclear power plant; fresh water #contaminated with effluent at a #SewageTreatmentPlant, or the valves in an #OilPipeline opened, contaminating the land or sea.
“'Giving an attacker control of industrial systems like a #dam, a sewage plant or a power station is extremely unusual and makes this a serious threat with huge real world implications,' says Patrick Fitzgerald, senior threat intelligence officer with Symantec. 'It has changed everything.'
Why is a different type of worm needed to attack an industrial plant?
"Industrial machinery is not controlled directly by the kind of computers we all use. Instead, the equipment used in an industrial process is controlled by a separate, dedicated system called a programmable logic controller (#PLC) which runs supervisory control and data acquisition software (#SCADA).
"Running the SCADA software, the PLC controls the process at hand within strict safety limits, switching motors on and off, say, and emptying vessels, and feeding back data which may safely modify the process without the need for human intervention – the whole point of industrial automation.
So how does a worm get into the system?
"It is not easy because they do not run regular PC, Mac or Linux software. Instead, the firms who sell PLCs each have their own programming language – and that has made it tricky for hackers to break it.
"However there is a way in via the Windows PC that oversees the PLC’s operations. Stuxnet exploited four vulnerabilities in Microsoft Windows to give a remote hacker the ability to inject malicious code into a market-leading PLC made by German electronics conglomerate Siemens.
"That’s possible because PLCs are not well-defended devices. They operate for many years in situ and electronic access to them is granted via well-known passwords that are rarely changed. Even when Stuxnet was identified, Siemens opposed password changes on the grounds that it could cause chaos as older systems tried to communicate using old passwords.
Where did the initial Stuxnet infection come from?
"It appears to have first arrived in Iran on a simple #USBMemoryStick, says Fitzgerald. His team in Dublin, Ireland has been analysing Stuxnet since it was first identified by a security team in Belarus in June.
"The first of the four Windows vulnerabilities allowed executable code on a USB stick to spread to a PC. The USB may have been given to an Iranian plant operative – or simply left somewhere for an inquisitive person to insert into their terminal.
"Says Fitzgerald: 'It then spreads from machine to machine on the network, exploiting a second vulnerability to do so, and reports back to the attacker on the internet when it finds a PC that’s running Siemens SCADA software. The attacker can then download a diagram of the industrial system set-up the SCADA controls.'
"The next two Windows vulnerabilities lets the worm escalate its privilege levels to allow the attacker to inject Siemens PLC format computer code – written in a language called STL – into the PLC. It’s that code which is capable of performing the skulduggery: perhaps turning off alarms, or resetting safe temperature levels.
How do we know where Stuxnet is active?
"Symantec monitored communications with the two internet domains that the worm swaps data with. By geotagging the IP addresses of Stuxnet-infected computers in communication with the attacker, Fitzgerald’s team found that 58.8 per cent of infections were in Iran, 18.2 per cent in #Indonesia, 8.3 per cent in #India, 2.6 per cent in #Azerbaijan and 1.6 per cent in the US.
Who is behind the worm?
"No one knows. It is however very professionally written, requiring what Fitzgerald calls 'a broad spectrum of skills' to exploit four new vulnerabilities and develop their own SCADA/PLC set-up to test it on.
"This has some commentators suggesting that a #NationState with plenty of technical resources may have been behind Stuxnet. But computer crime is a billion dollar business so such an effort is not beyond extortionists.
"Stuxnet comprises a 600-kilobyte file and it has not yet been fully analysed."
Read more:
https://www.newscientist.com/article/dn19504-why-the-stuxnet-worm-is-like-nothing-seen-before/